Effective date: July 13, 2026
QueryCut ("the Service", "we", "us") is an AI negative-keyword tool for Google Ads. This policy explains what data we access, what we store, and what we never do with it. The short version: we read your search terms to build recommendations, we don't store your reports, and we never sell or share your data.
QueryCut's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google Ads data is used only to provide the analysis features you request; it is not transferred to third parties except as necessary to provide those features (see "Service providers" below), not used for advertising, and never sold. Humans do not read your data except with your permission, for security purposes, or as required by law.
When you connect Google Ads, we store an encrypted OAuth token that lets the Service read your search terms on your behalf. You can revoke this access at any time at myaccount.google.com/permissions, which immediately invalidates our access.
Analysis is performed using third-party AI infrastructure: Anthropic (language analysis) and OpenAI (semantic embeddings). Search terms are sent to these providers solely to generate your report and are subject to their API data-usage policies, which do not permit training on API data. Hosting and database services are provided by Railway. Optional report emails are sent via Resend. Payments are processed by Stripe, which receives your email address and payment details; Stripe never receives any of your Google Ads data.
Reports you run interactively are never stored (see section 3); scheduled reports are stored encrypted and deleted after at most 30 days. What we retain while you use the Service: your account details, usage counts, and the distilled learnings described in section 2. Your encrypted Google OAuth token is retained only while your Google Ads account is connected — disconnecting inside the app, or revoking access at myaccount.google.com/permissions, deletes or invalidates it immediately. You may request deletion of all data associated with your account at any time by emailing hello@negativekeywordlist.com — we will delete it within 30 days and confirm.
All traffic is encrypted in transit (TLS). Google OAuth tokens are encrypted at rest with a dedicated key held separately from the database. Passwords are stored only as salted cryptographic hashes. Google Ads data is processed in memory for the duration of your analysis and is not written to disk. Access to production systems is restricted to authorized personnel, and sign-in endpoints are rate-limited to resist automated attacks.
We'll post any changes to this policy on this page and update the effective date above. Material changes will be announced to registered users by email.
QueryCut · hello@negativekeywordlist.com